Identity governance
Access packages, entitlement management, and lifecycle workflows — built the way a real organization would need them, then tested against the approval delays and orphaned assignments that a demo never shows.
A dedicated Microsoft 365 tenant, an on-prem directory nobody depends on, and enough distance from anything customer-facing that an experiment is allowed to fail badly.
Most guidance on Entra ID, Defender, and Zero Trust either comes from a vendor deck or a production environment where nobody can afford to find the edge cases. This lab exists to find them anyway — in a tenant built specifically to be pushed until something breaks, then written up honestly about what that was.
Everything here is non-production and personally owned. That separation is deliberate: it means a conditional access policy can be misconfigured on purpose, a detection can be tuned against real noise, and a migration pattern can be tried twice before it's trusted once.
Modest by design. If a finding only holds in an environment with a dedicated identity team behind it, it isn't a useful finding for most people reading it.
These overlap more than the section headers suggest. An identity experiment usually ends up being a detection experiment, and vice versa.
Access packages, entitlement management, and lifecycle workflows — built the way a real organization would need them, then tested against the approval delays and orphaned assignments that a demo never shows.
Defender for Endpoint, Defender for Identity, and Defender for Cloud Apps, tuned and correlated through XDR. The interesting part is rarely the alert — it's what the correlation misses.
Writing detections in KQL, then running simulated activity against them so a false-positive rate exists before anything reaches a queue that pages a human.
Conditional access policy design, device compliance, and the segmentation choices that decide whether "verify explicitly" holds up once real users start filing tickets about it.
Legacy AD DS patterns moving onto native Entra ID Governance — sync engine behavior, hybrid join edge cases, and the migration sequencing that determines whether a cutover is boring or not.
Graph and PowerShell automation, and agent-security work that borrows its threat model directly from the identity work above — an agent with credentials is an identity problem first.
A control doesn't count as validated until something has tried to get past it. Every policy and detection on this site gets tested against activity designed to break it, not just activity designed to demonstrate it.
A detection that catches everything and also fires on a normal Tuesday isn't finished. Every detection write-up here includes both numbers.
An experiment that fits in a weekend gets written up. One that takes a quarter becomes half-finished notes nobody reads. Scope is set accordingly — a deliberately smaller ambition than the diversified-conglomerate pitch the name is borrowed from, but a finished experiment beats an unfinished empire.
Everything on this site comes from a personally owned lab tenant. No customer data, no employer configuration detail, and no finding that could be mistaken for a disclosure about a specific organization's environment. If a page reads as generic, that's on purpose.
Each one carries the tenant configuration, what was measured, and what broke on the way there.